Source hostname instead of source_ip

Hello, is there any way to have a source_hostname instead of source_ip. I am looking to monitor traffic data and it seems there is only a choice by IP but hostname would be more useful since we wouldn't have to keep track of every IP.

Thanks,
Kenny

Are you referring to the monitoring module that comes with X-Pack?

no packetbeat,

i would like to use hostnames instead of IP's

What hostname would you like to see? What protocols are you talking about here?

There is a reverse lookup filter in Logstash that can add hostnames to events.

how can this be done through logstash? is there a way to do this through elasticsearch as i am not sending any packetbeats to logstash.

You need Logstash for that. See https://www.elastic.co/guide/en/logstash/current/plugins-filters-dns.html

ok, ill give this a shot thanks!

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.